We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The most comprehensive horizontal AI regime in force. It classifies AI systems by risk, places the heaviest duties on high-risk uses, and reaches any provider or deployer whose system touches the EU market, wherever they are established. Here is what it asks, of whom, and by when.
The Act does not regulate AI as a single thing. It sorts each system into a risk tier and attaches obligations to the tier: a small set of practices are banned outright, a defined list of high-risk uses carry the full compliance burden, a few uses owe only transparency, and everything else is largely unregulated.
It is also extraterritorial. The obligations follow the system into the EU market, so a provider outside the EU placing a system on the market, and a deployer using one whose output is used in the EU, are both in scope. And it is a moving regime: the 2026 Digital Omnibus postponed the heaviest high-risk deadlines while leaving the literacy, transparency, and prohibition duties on their original clock.
Banned practices: social scoring, manipulative or exploitative AI, untargeted scraping for facial recognition, and more.
Employment, credit, education, biometrics, essential services, critical infrastructure. The full obligation set.
Chatbots, emotion recognition, and synthetic or manipulated content must disclose that AI is at work.
Everything else. No mandatory obligations under the Act; voluntary codes of conduct are encouraged.
Application phases in over several years. The Digital Omnibus (political agreement May 2026) moved the standalone high-risk deadline to December 2027, but left the earlier duties in place.
Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply.
General-purpose AI model obligations (Art. 51–55) apply.
Article 50 transparency obligations apply; synthetic-content marking follows in Dec 2026.
Standalone high-risk (Annex III) obligations apply; product-embedded (Annex I) follows 2 Aug 2028.
Source: Official Journal of the EU · EU AI Act as amended by the Digital Omnibus · confirm against consolidated text before relying on any date
The same system carries different duties depending on whether you build it, deploy it, import it, or represent a provider from outside the EU.
The heaviest duties. Risk management, data governance, technical documentation, logging, human oversight, conformity assessment, registration, and post-market monitoring.
Operate it as instructed, keep human oversight, monitor for issues, and run a fundamental-rights impact assessment where required. Data-protection duties run in parallel.
Verify the provider completed conformity assessment, that documentation and the CE marking are in place, before the system reaches the market.
The provider's EU point of contact. Hold the documentation, cooperate with authorities, and be the address the regulator can reach.
Roles and duties render from structured regulatoryProvision records · illustrative, not exhaustive
Fines are set as the higher of a fixed ceiling or a percentage of worldwide annual turnover. For SMEs and start-ups, the lower of the two applies.
| Breach | What it covers |
|---|---|
| €35M / 7%whichever is higher | Deploying a prohibited AI practice under Article 5. |
| €15M / 3%whichever is higher | Non-compliance with most other obligations, including the high-risk provider and deployer duties. |
| €7.5M / 1%whichever is higher | Supplying incorrect, incomplete, or misleading information to authorities. |
Figures per the EU AI Act penalty tiers · confirm the applicable ceiling and any Omnibus adjustment against the consolidated text
"We're not an EU company, so it doesn't apply to us."
The Act is extraterritorial. If your system is placed on the EU market, or its output is used in the EU, you are in scope wherever you are established.
"We don't build AI, we only use it, so the burden is the vendor's."
Deployers carry their own duties: human oversight, monitoring, and a fundamental-rights impact assessment where required. The Article 4 literacy duty has applied to every deployer since February 2025.
"The deadline moved to 2027, so there's time to wait."
Standalone high-risk obligations now apply from 2 December 2027, but literacy is live, transparency lands in August 2026, and prohibitions are already in force. The extra time is for doing the work properly before the standards land, not for delay.
Yes. The Act binds deployers, not only providers. If you put an AI system into use under your own authority in the EU, you carry deployer obligations under Article 26, and for certain high-risk uses a fundamental-rights impact assessment under Article 27, regardless of who built the system.
Article 99 sets three tiers, each the higher of a fixed sum or a percentage of global annual turnover: up to EUR 35 million or 7% for prohibited practices (Article 5); up to EUR 15 million or 3% for breaching high-risk or other obligations; and up to EUR 7.5 million or 1% for supplying incorrect or misleading information.
The Act applies in phases. The Article 5 prohibited-practice bans and AI-literacy duties applied from 2 February 2025; general-purpose AI model rules from 2 August 2025; most high-risk obligations from 2 August 2026; and high-risk systems that are safety components of regulated products from 2 August 2027.
No. The provider's Article 9 risk assessment addresses engineering risks; the deployer's fundamental-rights impact assessment under Article 27 assesses impact on affected persons' rights in the deployer's particular deployment context. Both are required and serve different purposes.
Article 99 requires penalties to be proportionate, taking into account the organisation's size and economic viability alongside the nature and gravity of the infringement. This can reduce the quantum but does not eliminate enforcement risk.
Not automatically. The high-risk classification under Article 6 and Annex III turns on the use case (for example recruitment, worker management, or access to essential services), not on whether the system is sold externally. An in-house high-risk deployment still triggers the deployer obligations.
The same high-risk system usually meets the GDPR, NIS2, DORA, sectoral law, and the Product Liability Directive at once. Standard Intelligence maps at the level of the obligation across every regime, so one body of evidence holds across all of them.